Certified Internal Auditor Certified Internal Auditor 4 — Questions and Answers
Question 1: An internal auditor discovers during fieldwork that the scope of the engagement must be expanded due to newly identified risks. The auditor should:
- Complete the original scope and ignore the new risks
- Immediately expand scope without informing management
- Discuss the scope expansion with the CAE and communicate changes to management (Correct answer)
- Transfer the engagement to another auditor
Correct answer: Discuss the scope expansion with the CAE and communicate changes to management
Scope changes require discussion with the CAE and communication to management to ensure appropriate resources and approvals are obtained.
Question 2: Which of the following BEST describes a 'key risk indicator' (KRI)?
- A measure that signals the effectiveness of a completed audit
- A forward-looking metric that provides early warning of increasing risk exposure (Correct answer)
- A historical report of past losses and control failures
- A benchmark comparing the company's risk to industry peers
Correct answer: A forward-looking metric that provides early warning of increasing risk exposure
KRIs are forward-looking metrics used to signal rising risk levels before they materialize into losses or control failures.
Question 3: Under the IIA Standards, internal auditors must disclose all material facts known to them that, if not disclosed, would distort the report. This is an element of which attribute?
- Independence
- Objectivity (Correct answer)
- Proficiency
- Confidentiality
Correct answer: Objectivity
Objectivity requires internal auditors to disclose all material facts to prevent reports from being misleading or incomplete.
Question 4: An auditor testing IT controls discovers that application access logs are not reviewed regularly. This finding BEST relates to which type of IT control weakness?
- Logical access control
- Change management control
- Monitoring control (Correct answer)
- Data backup control
Correct answer: Monitoring control
Failure to regularly review access logs is a weakness in monitoring controls, which are designed to detect inappropriate or unauthorized activity.
Question 5: Which engagement planning step requires the auditor to obtain background information about the processes and risks of the area under review?
- Fieldwork
- Preliminary survey (Correct answer)
- Final communication
- Follow-up
Correct answer: Preliminary survey
A preliminary survey gathers background information about the auditable unit to help the auditor understand risks and focus the engagement.
Question 6: An audit report is MOST effective when findings are communicated using which structure?
- Condition, criteria, cause, effect, and recommendation (Correct answer)
- Objectives, scope, timing, and budget
- Risk rating, control type, test method, and sample size
- Background, findings, management response, and timeline
Correct answer: Condition, criteria, cause, effect, and recommendation
The condition-criteria-cause-effect-recommendation structure provides a complete, logical presentation of audit findings.
Question 7: When assessing enterprise risk management (ERM), internal auditors should PRIMARILY evaluate:
- Whether the ERM process aligns with the organization's risk appetite and objectives (Correct answer)
- Whether all identified risks have been eliminated
- The number of risk categories monitored by management
- Whether external auditors have approved the ERM framework
Correct answer: Whether the ERM process aligns with the organization's risk appetite and objectives
The key ERM assessment is whether the process is designed and operating to manage risks within the organization's stated risk appetite and support its objectives.
An internal auditor discovers during fieldwork that the scope of the engagement must be expanded due to newly identified risks.
The auditor should: